cbcvebase.
CVE-2022-4361
published 2023-07-07

CVE-2022-4361: Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.

Affected

9 ranges
VendorProductVersion rangeFixed in
googlechrome_chrome
redhatkeycloak< 21.1.221.1.2
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatsingle_sign-on>= 7.6 < 7.6.47.6.4